MEDIUM 6.5 GitHub
CVE-2026-48786
Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint
### Summary
The target search endpoint (`POST /api/latest/fleet/targets`) returned team enroll secrets and full team configuration, including credential-bearing agent options, to observer-class users. Other team-facing endpoints mask these fields for observers; the target search endpoint did not apply the same sanitization.
### Impact
An authenticated user with Observer, Observer+, or Technician role (global or team-scoped) could retrieve unmasked team enroll secrets and team agent options by
Affected Products
- go/github.com/fleetdm/fleet/v4 < 4.87.0
References
- https://github.com/advisories/GHSA-88p2-jj8w-j8qg
- https://github.com/fleetdm/fleet/security/advisories/GHSA-88p2-jj8w-j8qg
- https://github.com/fleetdm/fleet/releases/tag/fleet-v4.87.0
- https://github.com/advisories/GHSA-88p2-jj8w-j8qg
This medium severity vulnerability with a CVSS score of 6.5 was published on 2026-08-12 via GitHub. Affected: go/github.com/fleetdm/fleet/v4 < 4.87.0.
vulnfeed aggregates 10467 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.